Malware

What is “VirTool:Win32/VBInject.DS”?

Malware Removal

The VirTool:Win32/VBInject.DS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/VBInject.DS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VirTool:Win32/VBInject.DS?


File Info:

name: 7C415FCFFFC3F91FCAEE.mlw
path: /opt/CAPEv2/storage/binaries/2cc82640f6ae8bec1824d2d2293872a84381c839eea3eb68a624af8bd2cca696
crc32: E5471CB6
md5: 7c415fcfffc3f91fcaee9bc2135828e4
sha1: 0f1f60040a96d34922d312706460c1d0442651b1
sha256: 2cc82640f6ae8bec1824d2d2293872a84381c839eea3eb68a624af8bd2cca696
sha512: 27b7634d6954b1117ea2dfa927419e8ff08a18a6af0613866512578692c2ad4c9ab1f17578d91097664157c9f7441dfdaef46b14ba8d8018dfe584be8a558478
ssdeep: 24576:ANy7xS1bQUu9jSdHirTxDjkt9u930tt6NBdl2NiWeVm4MmvX40CW+ldyVbI:KYxS103SdCHxDIvu930jdNiWehv52UbI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C845337F95E49802CA1EC435872BD3A93A61FFDB9E1D2E9E22984EA45430D502D3DC73
sha3_384: 9d76e60bc2b6060c9c1ebf60ca4f75345d8794a9953e296bbcad93d5d8ae67a2d6ae2806d02f3daa65b53b376043f3d3
ep_bytes: 680c124000e8eeffffff000000000000
timestamp: 2009-08-02 20:04:21

Version Info:

CompanyName:
ProductName:
FileVersion:
ProductVersion:
InternalName:
OriginalFilename:
Translation: 0x0409 0x04b0

VirTool:Win32/VBInject.DS also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.26012
ALYacGen:Variant.Jaik.26012
CylanceUnsafe
SangforVISUAL BASIC4
BitDefenderGen:Variant.Jaik.26012
Cybereasonmalicious.fffc3f
CyrenW32/Trojan.IJXV-6813
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Spy.Zbot.NJ
APEXMalicious
ClamAVWin.Trojan.Zbot-7065
KasperskyWorm.Win32.VBNA.b
RisingTrojan.Spy.Win32.Zbot.fre (CLASSIC)
Ad-AwareGen:Variant.Jaik.26012
EmsisoftGen:Variant.Jaik.26012 (B)
ComodoTrojWare.Win32.Spy.Zbot.NJ3@1r3afr
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Spambot.4615
ZillyaTrojan.Zbot.Win32.7419
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.7c415fcfffc3f91f
SophosML/PE-A + Mal/VBDrop-G
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Jaik.26012
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.F400B7
ArcabitTrojan.Jaik.D659C
ZoneAlarmWorm.Win32.VBNA.b
MicrosoftVirTool:Win32/VBInject.DS
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Buzus.R3251
Acronissuspicious
MAXmalware (ai score=87)
MalwarebytesMalware.AI.2892063539
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!ghpj5FlhK0k
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.C!tr
BitDefenderThetaAI:Packer.44EAD0D51F
AVGWin32:Inject-ABT [Trj]
AvastWin32:Inject-ABT [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove VirTool:Win32/VBInject.DS?

VirTool:Win32/VBInject.DS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment